CVE-2026-2106 is an improper authorization vulnerability affecting the yeqifu warehouse product, specifically within the Notice Management component's addNotice/updateNotice/deleteNotice/batchDeleteNotice functions. This flaw allows an authenticated attacker to remotely manipulate notice data, leading to high impacts on confidentiality, integrity, and availability. With a CVSS score of 8.8 (High), the exploit has been publicly disclosed, though no active exploitation or exploit code (Metasploit, Nuclei, ExploitDB) has been observed. Despite public disclosure, there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-10-06CPE matchmatch criteria | cpe:2.3:a:yeqifu:warehouse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.